<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: NRF + PCI = CIO Job Security</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/nrf-pci-cio-job-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/nrf-pci-cio-job-security/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 03:42:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Mark Bower</title>
		<link>http://storefrontbacktalk.com/securityfraud/nrf-pci-cio-job-security/comment-page-1/#comment-64348</link>
		<dc:creator>Mark Bower</dc:creator>
		<pubDate>Fri, 15 Jan 2010 19:58:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4545#comment-64348</guid>
		<description>A nice summary. NRF was certainly buzzing around true End-to-end encryption and tokenization. We&#039;re not taking point to point. End-to-End is from swipe to acquirer, and/or swipe to PAN dependent merchant system - something only possible with new approaches I&#039;ve mentioned here in the past.

What was interesting to me was seeing the contrast in the efforts of various approaches being tried. Some merchants we met for the first time had been struggling for 2 years already or more trying to achieve this and still stuck in pilot with older style tokenization and legacy encryption which struggles when it comes to the change impact in legacy hardware/software and when taking into account critical back office functions like velocity checking and fraud investigations, e-discovery etc. When I described how we&#039;d already taken Tier 1&#039;s through this to PCI compliance in a fraction of that time with Format Preserving Encryption there was a lot of excitement - these new approaches avoid exactly the change impact they were struggling with in integrating encryption and tokenization into the complex merchant legacy environment and processes.

Another highlight for me was how many merchants really do see the need to go well beyond PCI DSS which as you note is falling behind the fast path merchants are heading in new areas like mobility - what a hot topic at NRF! Merchants not only want to explore new payments acceptance like mobile, but want to also cover employee data, partner communications, and other privacy regulated data in a single swoop. Of course, our conversations drift to those areas as we solve those challenges too with our overall data protection platform - but it was striking nonetheless. The concern being what&#039;s the point of investing several million in PCI compliance and focus just on credit card data and and leaving equally sensitive data at risk - SSN&#039;s, Tax Data, competitive strategy information, HR data on vast numbers of past and present employees in a very high staff turnover business.

So from uplifting show at NRF I see 2010 being one of not only E2E and Tokenization in the payments side, but solving the big picture - sensitive data organization wide. That&#039;s where the real ROI will be for merchants in data protection investments. No point being the front page breach news if your systems are compromised and all your employee data is exposed - its the same reputation and brand damage impact.</description>
		<content:encoded><![CDATA[<p>A nice summary. NRF was certainly buzzing around true End-to-end encryption and tokenization. We&#8217;re not taking point to point. End-to-End is from swipe to acquirer, and/or swipe to PAN dependent merchant system &#8211; something only possible with new approaches I&#8217;ve mentioned here in the past.</p>
<p>What was interesting to me was seeing the contrast in the efforts of various approaches being tried. Some merchants we met for the first time had been struggling for 2 years already or more trying to achieve this and still stuck in pilot with older style tokenization and legacy encryption which struggles when it comes to the change impact in legacy hardware/software and when taking into account critical back office functions like velocity checking and fraud investigations, e-discovery etc. When I described how we&#8217;d already taken Tier 1&#8242;s through this to PCI compliance in a fraction of that time with Format Preserving Encryption there was a lot of excitement &#8211; these new approaches avoid exactly the change impact they were struggling with in integrating encryption and tokenization into the complex merchant legacy environment and processes.</p>
<p>Another highlight for me was how many merchants really do see the need to go well beyond PCI DSS which as you note is falling behind the fast path merchants are heading in new areas like mobility &#8211; what a hot topic at NRF! Merchants not only want to explore new payments acceptance like mobile, but want to also cover employee data, partner communications, and other privacy regulated data in a single swoop. Of course, our conversations drift to those areas as we solve those challenges too with our overall data protection platform &#8211; but it was striking nonetheless. The concern being what&#8217;s the point of investing several million in PCI compliance and focus just on credit card data and and leaving equally sensitive data at risk &#8211; SSN&#8217;s, Tax Data, competitive strategy information, HR data on vast numbers of past and present employees in a very high staff turnover business.</p>
<p>So from uplifting show at NRF I see 2010 being one of not only E2E and Tokenization in the payments side, but solving the big picture &#8211; sensitive data organization wide. That&#8217;s where the real ROI will be for merchants in data protection investments. No point being the front page breach news if your systems are compromised and all your employee data is exposed &#8211; its the same reputation and brand damage impact.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

